Google wants to make sideloading Android apps safer by verifying developers’ identities
https://androidauthority.com/android-developer-verification-requirements-3590911/
https://androidauthority.com/android-developer-verification-requirements-3590911/
49 Comments
the_riviera_kid@lemmy.world · 190 pts · 354d
An accurate title would read something like: Google wants to make side loading apps more difficult by adding extra steps under the guise of security in order to maintain market dominance and continue spying on the user.
BlackEco@lemmy.blackeco.com · 101 pts · 354d
Yay, Google adding another hurdle for alternative app stores and their developers...
Hirom@beehaw.org · 52 pts · 354d
F-Droid store/repo is safer than Google Play Store. Google's own store has many shady apps, including spyware and occasionnal malware.
I don't get the argument that Play Store is safer than others.
steal_your_face@lemmy.ml · 17 pts · 354d
Google play services is spyware
spaghettiwestern@sh.itjust.works · 65 pts · 354d
I know my sideloaded apps are safe. I have far less confidence with the apps Google allows in their App Store.
limerod@reddthat.com · 44 pts · 354d
Ridiculous, mother of bullshit! Switching to Linux appears to be the only option left for a personal computing device.
unknownuserunknownlocation@kbin.earth · 15 pts · 354d
I really hope phones get better Linux support soon... it really isn't daily driver material for most phones at the moment.
balder1991@lemmy.world · 6 pts · 354d
In this time and age, do you still doubt that Linux might be outlawed for consumers? To prevent criminal activity, of course /s.
limerod@reddthat.com · 8 pts · 353d
They already consider you a criminal if you use grapheneOS on a pixel. It's not a joke.
tinned_tomatoes@feddit.uk · 3 pts · 353d
Just turn off Google Play Protect and it'll let you sideload whatever you want.
Draconic_NEO@lemdro.id · 2 pts · 353d
You can't seriously actually trust that turning it off in the Google owned app they control or update will be meaningful. I'm really sick of people claiming it is, and I hope this will get them to realize that.
If you want to crush it fully, disable google play store as a whole, and make sure to tell your friends too because if that solution doesn't get more popular there might not be third party apps to install since the devs will just quit.
tinned_tomatoes@feddit.uk · 1 pts · 352d
I dunno, you're the one claiming stuff that isn't necessarily true (yet). This is a proposed update to Google Play Protect. You don't have to have Google Play Protect enabled, and disabling it doesn't really impact anything unless you're the type of person to just download an apk from unverified sources.
Infernal_pizza@lemmy.dbzer0.com · 1 pts · 352d
Where did you hear this? I've seen a couple of articles on this now but none of them have mentioned its specifically play protect or that it can be turned off
limerod@reddthat.com · 0 pts · 353d
I keep play protect enabled in case I download anything unsafe.
tinned_tomatoes@feddit.uk · 2 pts · 352d
Not really necessary if you limit your APK sources to trusted sources like apkmirror or github.
limerod@reddthat.com · 0 pts · 352d
Github is not a trusted source. Anyone can dump apk files over there.
possiblylinux127@lemmy.zip · 1 pts · 354d
Honestly we need a community OS like Android/Chome OS
I like Linux but it would be really cool to have a OS that was less modular and more purpose built. I feel like there is enough people interested that we could raise some money to hire some developers. On think Chome OS and Android get right is the hassle free unified experience.
db2@lemmy.world · -8 pts · 354d
Wait until you find out what Android is under the UI.
limerod@reddthat.com · 31 pts · 354d
While its true Android runs on the Linux kernel, its not Linux. There are many differences and restrictions.
possiblylinux127@lemmy.zip · 6 pts · 354d
rips off mask
It is a vendor kernel!
Schwim@lemmy.zip · 41 pts · 354d
Sure, to make it safer in the same way Microsoft made you safer by making it harder to install Linux with UEFI.
agelord@lemmy.world · 5 pts · 354d
Isn't it actually easier with UEFI since you can have multiple bootloaders and updating windows doesn't overwrite any other bootloaders? I think the issue arises from secureboot
moonpiedumplings@programming.dev · 1 pts · 353d
The person you replied to is probably talking about this: https://wiki.debian.org/UEFI#Force_grub-efi_installation_to_the_removable_media_path
carrylex@lemmy.world · 38 pts · 354d
kokesh@lemmy.world · 37 pts · 354d
Let Android be free, fuck off Google.
halfapage@lemmy.world · 12 pts · 354d
0_o7@lemmy.dbzer0.com · 11 pts · 354d
You can't convince me this wasn't Google's plan from the very beginning.
They stole tons of features from custom ROMs but never implemented the ability to turn off internet for specific apps so they could push ads and track users.They made turning location "on" a requirement to scan wifi, calling it a security feature. They re-enable "background data" on all apps with an Android update. These are just off the top of my head.
Chromium works towards same goal as well. They never wanted to defeat apple, monopoly, they wanted to become part of the duopoly.
noxypaws@pawb.social · 29 pts · 354d
At some point that stops being sideloading.
BeatTakeshi@lemmy.world · 1 pts · 353d
( ͡° ͜ʖ ͡°)
SoftestSapphic@lemmy.world · 18 pts · 353d
I've never wanted to get all my devices totally detached from google until recently.
They are going full mask off right now.
They're prepping to be the surveillance service for the global fascist oligarchy.
MicrowavedTea@infosec.pub · 17 pts · 354d
In the meantime, we're already verifying signatures for sideloaded apps. Can't say the same about play store apps.
TheBat@lemmy.world · 16 pts · 354d
Turret3857@infosec.pub · 12 pts · 354d
Fairphone have 7 years of guaranteed support, possibly longer with custom Roms. :P
TheBat@lemmy.world · 4 pts · 354d
DeathByBigSad@sh.itjust.works · 2 pts · 353d
Clove Technology ships worldwide, but you might have to deal with your country's customs and might have to pay import fees.
Limonene@lemmy.world · 1 pts · 352d
Even if you can buy it, you can't file a warranty return if you are outside Fairphone's small support area.
PresidentCamacho@lemmy.ca · 1 pts · 352d
Fairphone run android tho?
Turret3857@infosec.pub · 1 pts · 351d
https://devices.ubuntu-touch.io/device/fp4/
Limonene@lemmy.world · 0 pts · 352d
Fairphone has guaranteed 0 years of support in my country.
SoftestSapphic@lemmy.world · -2 pts · 353d
Fairphone will no longer allow custom roms
archchan@lemmy.ml · 13 pts · 354d
Year of the Linux phone in 2026?
LiveLM@lemmy.zip · 8 pts · 354d
Great, Apple style app notarization is just about the last thing I want on my damn phone.
flop_leash_973@lemmy.world · 7 pts · 353d
Every year that goes by mobile computing gets less and less interesting.
Might as well just buy the cheapest one that will do the job and call it done. So sense in spending top dollar very often when it is just a severely limited black box, like a video game console.
shortwavesurfer@lemmy.zip · 7 pts · 354d
Glad i run only LineageOS with no gapps.
I wonder if this will do the same thing that happened to Windows when Windows 11 wouldn't support older devices and people switched on mass to Linux.
Either way, you're gonna have a bifurcated Android. One Android for the plebs where Google controls everything, and one Android for those who know where Google controls nothing.
Sounds like this is going to stop things like me telling my friend to install new pipe from afteroid because they can skip YouTube ads.
y0kai@lemmy.dbzer0.com · 5 pts · 352d
Lmao "safer" FOH monopolistic pieces of shit.
tomyhaw@lemmy.world · 4 pts · 354d
Oh I see someone already made a post. I can't see how this is enforceable except for highly modifying the OS. It would have to be enforced at the device level correct,?
73QjabParc34Vebq@piefed.blahaj.zone · 19 pts · 354d
It'll be part of Google Play "Protect", part of "gapps" not AOSP. Manufacturers have to ship all of gapps or none. Its not clear if this will block installs/updates, add a nag screen occasionally or fully block running these apps/disable them.
This is the equivalent of Apples Notarization which they just used to block apps after the EU told them to allow users to install apps.
DoucheBagMcSwag@lemmy.dbzer0.com · 5 pts · 354d
So disable play protect and this goes away
Edit: I do want to add that I HOPE this is what is needed to bypass this... If they block my modded and github APKs I'm going to go fucking nuclear
EDIT: further research shows this will not be based on play protect but will be implemented in the APK itself. I hope this shit can be patched out because you know Google is doing to do this with YouTube to kill revanced
Draconic_NEO@lemdro.id · 3 pts · 353d
You'll probably have to disable Play Store for it to go away, Turning off Play Protect isn't very effective anyway. Even with it off it has still disabled apps automatically and warned me. I disabled Play Store and the behavior went away.
I think you might be confusing this with App Integrity which Google offers to developers to include in their apps, this change is to prevent people from installing their own apps, likely with a dialogue to interrupt it. Play Protect can already interrupt installations asking you to agree or not. That's in all likelihood the mechanic they'll use to enforce this.
ohellidk@sh.itjust.works · 3 pts · 354d
Can this be bypassed by using adb to sideload, I wonder?
Draconic_NEO@lemdro.id · 2 pts · 353d
Probably not, but I imagine that disabling or uninstalling the play store will bypass it since it'll likely use the Play Protect Dialogue injection in Package Installer to bounce inauthentic installations.
cupcakezealot@piefed.blahaj.zone · 3 pts · 354d
can they not just develop a method like they do for verifying websites with an .android folder or something? requiring everyone into a centralised place is garbage.